Adding Azure AD group to local group fails

Tim 96 Reputation points

The command below fails with error "there is no such global user or group: AzureAd\groupname@keyman .com"

net localgroup administrators "AzureAD\groupname@keyman .com" /Add

I have tried using the SID, no AzureAD, and no domain and all return the same error.

However I can run the same command with a user account and it is successful.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,802 questions
{count} votes

Accepted answer
  1. Tim 96 Reputation points

    The "NET" command seems to be geared more towards AD and using it with AAD produces mixed/unexpected results.


    Create a new Configuration Profile and choose Custom.


    <accessgroup desc = "Administrators">
    <group action = "U"/>
    <add member = "AzureAD Group's SID"/>

1 additional answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 34,626 Reputation points Microsoft Employee

    This recommended approach is to sync the local group to Azure AD instead, as Microsoft does not have official guidelines adding groups to a group synced with an on-premises Azure AD.

    There is also an open feedback request for this:

    That said, this blog post shows how to add an Azure AD group to a local admin group using Intune: